Nurgle: Exacerbating Resource Consumption in Blockchain State Storage via MPT Manipulation
Zheyuan He, Zihao Li, Ao Qiao, Xiapu Luo, Xiaosong Zhang, Ting Chen, Shuwei Song, Dijun Liu, Weina Niu
摘要
Blockchains, with intricate architectures, encompass various components, e.g., consensus network, smart contracts, decentralized applications, and auxiliary services. While offering numerous advantages, these components expose various attack surfaces, leading to severe threats to blockchains. In this study, we unveil a novel attack surface, i.e., the state storage, in blockchains. The state storage, based on the Merkle Patricia Trie, plays a crucial role in maintaining blockchain state. Besides, we design Nurgle, the first Denial-of-Service attack targeting the state storage. By proliferating intermediate nodes within the state storage, Nurgle forces blockchains to expend additional resources on state maintenance and verification, impairing their performance. We conduct a comprehensive and systematic evaluation of Nurgle, including the factors affecting it, its impact on blockchains, its financial cost, and practically demonstrating the resulting damage to blockchains. The implications of Nurgle extend beyond the performance degradation of blockchains, potentially reducing trust in them and the value of their cryptocurrencies. Additionally, we further discuss three feasible mitigations against Nurgle. At the time of writing, the vulnerability exploited by Nurgle has been confirmed by six mainstream blockchains, and we received thousands of USD bounty from them.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Enhancing the Open Network: Definition and Automated Detection of Smart Contract DefectsHao Song, Teng Li, Jiachi Chen, Ting Chen 等ICSE 2025 · 被引用 5 次
- fAmulet: Finding Finalization Failure Bugs in Polygon zkRollupZihao Li, Xinghao Peng, Zheyuan He, Xiapu Luo 等CCS 2024 · 被引用 5 次
- Towards Automatic Discovery of Denial of Service Weaknesses in Blockchain Resource ModelsFeng Luo, Huangkun Lin, Zihao Li, Xiapu Luo 等CCS 2024 · 被引用 4 次
- Maat: Analyzing and Optimizing Overcharge on Blockchain StorageZheyuan He, Zihao Li, Ao Qiao, Jingwei Li 等FAST 2025 · 被引用 3 次
- Pistis: A Decentralized Knowledge Graph Platform Enabling Ownership-Preserving SPARQL QueryingEnyuan Zhou, Song Guo, Zicong Hong, Christian S. Jensen 等VLDB 2025 · 被引用 1 次
它引用的顶会 Paper25
- T-Fuzz: Fuzzing by Program TransformationHui Peng, Yan Shoshitaishvili, Mathias PayerS&P 2018 · 被引用 326 次
- SAILFISH: Vetting Smart Contract State-Inconsistency Bugs in SecondsPriyanka Bose, Dipanjan Das, Yanju Chen, Yu Feng 等S&P 2022 · 被引用 142 次
- TokenScope: Automatically Detecting Inconsistent Behaviors of Cryptocurrency Tokens in EthereumTing Chen, Yufei Zhang, Zihao Li, Xiapu Luo 等CCS 2019 · 被引用 140 次
- A Stealthier Partitioning Attack against Bitcoin Peer-to-Peer NetworkMuoi Tran, Inho Choi, Gi Jun Moon, Anh V. Vu 等S&P 2020 · 被引用 126 次
- Blockchains vs. Distributed Databases: Dichotomy and FusionPingcheng Ruan, Tien Tuan Anh Dinh, Dumitrel Loghin, Meihui Zhang 等SIGMOD 2021 · 被引用 68 次
相关 Paper
- MHOT: Height-Optimized Authenticated Data Structure for Blockchain State CommitmentSipeng Xie, Qianhong Wu, Minghang Li, Qiyuan Gao 等USENIX Security 2026 · 被引用 2 次
- Code is the (F)Law: Demystifying and Mitigating Blockchain Inconsistency Attacks Caused by Software BugsGuorui Yu, Shibin Zhao, Chao Zhang, Zhiniang Peng 等INFOCOM 2021 · 被引用 6 次
- Understanding Ethereum Mempool Security under Asymmetric DoS by Symbolized Stateful FuzzingYibo Wang, Yuzhe Tang, Kai Li, Wanning Ding 等USENIX Security 2024 · 被引用 9 次
- Content Censorship in the InterPlanetary File SystemSrivatsan Sridhar, Onur Ascigil, Navin V. Keizer, François Genon 等NDSS 2024
- BDoS: Blockchain Denial-of-ServiceMichael Mirkin, Yan Ji, Jonathan Pang, Ariah Klages-Mundt 等CCS 2020 · 被引用 1 次
